Hi all. We have PA-820 with 10.1.2 with User-ID Agent on Windows AD runing version 10.0.4-r23 and we are using Cisco switches for users. We have 802.1x enabled on ports for users. The problem we have is, that PA doesn't recognise users from 802.1x, instead sometimes they are recognised as machines (under Monitor->User-ID), and then it won't apply Security policies as it should. User passes 802.1x authentication as it should, he gets correct VLAN assigned and correct IP address. The same problems are on wired and on wireless. I suspect there is an issue with forwarding correct user from AD to User-ID Agent. I tried clearing test user in User-ID Agent on server, but no change. On AD in Windows Event viwer I can see user getting authenticated correctly in Security logs and under NPS logs. We have Server monitoring turned on and both AD servers are connected. When checking User-ID Agent on Windows server, there is missing the user I connected with. This is almost new setup and we are not sure, if it even worked from day 1. Is there any guide how to troubleshoot? Any idea what could be the reason for problems? Kind regards
... View more